MailScanner? But that only takes care of files that are being sent or received.

But it would mean that even if the users add a say .BAT file to an email and try to send it, it would then be blocked by MailScanner before they get to the recipient, either inside the network or outside (at least that’s how I have set it up).

We got a firewall with antispam/Virus-Filter - but this first security is not enough for some users, who unblock mails they dont know (even if they got different instructions).

So these unblocked mails are delivered to the inbox and thats not good.
i was told, that another 3rd-Party program is not an option.
The plugin or setting via config-file just need to prevent .zip files from loading and replace this with a message: “Blocked file: $blocked_file_name - contact yout IT” - or something like that.

I see. MailScanner (at least in my installation) doesn’t let the users unblock anything but they have to physically ask the admin to retrieve the attachment… A little bit more cumbersome but it’s all blocked.

The plugin perhaps would work, but the issue is, as I mentioned, renamed files.

Someone can simply rename a .zip file as .z1p and the plugin won’t block it, unless of course you add a lot more sophistication to the code.

well… the user can write in the email something like " I send you a zip file renamed as z1p" and you can save it and rename it and that will do the trick.

Anyway I am not saying a plugin or some settings somewhere in webapp to avoid uploading a certain set of extensions is a bad idea, just that it can be very simple (simply block the name) or very complicated depending on how much time and effort you want to invest to write this…